<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_12</id>
	<title>Secure Req 12 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_12"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_12&amp;action=history"/>
	<updated>2026-04-16T10:03:56Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Secure_Req_12&amp;diff=6574&amp;oldid=prev</id>
		<title>Omaerz: 9 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_12&amp;diff=6574&amp;oldid=prev"/>
		<updated>2018-06-28T04:03:34Z</updated>

		<summary type="html">&lt;p&gt;9 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Baseline_Functional_Requirements_v1.0|Baseline Functional Requirements Index]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== SECURE-12.    RECOVERY AND REISSUANCE ==&lt;br /&gt;
Entities that issue credentials and tokens MUST implement methods for reissuance, updating, and recovery of credentials and tokens that preserve the security and assurance of the original registration and credentialing operations.&lt;br /&gt;
&lt;br /&gt;
=== SUPPLEMENTAL GUIDANCE ===&lt;br /&gt;
Procedures must be in place to reasonably prevent hijacking of an account through recovery and&lt;br /&gt;
reset options: a common vector for identity thieves and other attackers. At a minimum, service&lt;br /&gt;
providers must provide reset, recovery, and reissuance procedures that afford a commensurate level of&lt;br /&gt;
security to the processes used during the initial registration and credentialing operations. These&lt;br /&gt;
procedures may include out-of-band verification, device identification, or any combination of similar&lt;br /&gt;
techniques used to increase the security of reset, reissuance, and recovery options while also meeting&lt;br /&gt;
[[Baseline_Functional_Requirements_v1.0#Usability|IDESG Usability Requirements]] (USABLE-1 through USABLE-7).&lt;br /&gt;
&lt;br /&gt;
=== REFERENCES ===&lt;br /&gt;
FICAM TFPAP Trust Criteria “Token &amp;amp; Credential Management”), LOA 2-3, #1, #2, #4, TFPAP Trust&lt;br /&gt;
Criteria, Management and Trust Criteria, LOA 2-3, #3,#4, #6 (p.35); PCI-DSS v 2.0- 8.5.2 (p. 48)&lt;br /&gt;
(corresponds to 8.2.2 in PCI-DSS v3. – p.67); NIST SP 800-63-2, Token and Credential Management&lt;br /&gt;
Activities 7.1.2 (p. 58)&lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ACTIVITIES ===&lt;br /&gt;
[[IDEF Functional Model REGISTRATION|REGISTRATION]], &lt;br /&gt;
[[IDEF Functional Model CREDENTIALING|CREDENTIALING]]&lt;br /&gt;
&lt;br /&gt;
=== KEYWORDS ===&lt;br /&gt;
[[IDEF Keywords ACCOUNT|ACCOUNT]], [[IDEF Keywords CREDENTIAL|CREDENTIAL]], [[IDEF Keywords EXPIRY|EXPIRY]], [[IDEF Keywords LOSS|LOSS]], &lt;br /&gt;
[[IDEF Keywords PROCESS|PROCESS]], [[IDEF Keywords PROVISIONING|PROVISIONING]], &lt;br /&gt;
[[IDEF Keywords RECOVERY|RECOVERY]], [[IDEF Keywords SECURITY|SECURITY]], [[IDEF Keywords TOKEN|TOKEN]]&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
Quick Links:   [[SALS]]  |  [[Baseline Functional Requirements v1.0]]  |  [[Glossary]]  |&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>